Security
Last updated 21 July 2026.
Encryption in transit
All traffic to and from Tenarize is served over HTTPS/TLS.
Encryption at rest
Passwords are hashed with bcrypt, never stored in plain text. Two-factor authentication secrets are encrypted at rest with AES-256-GCM. Our database and document storage are both encrypted at rest by our infrastructure providers.
Data residency
Our primary database and application hosting run in Frankfurt, Germany (EU). Our e-signature provider processes documents in the EU. See our Data Processing Agreement for the full sub-processor list and their locations.
Access controls
Landlord and tenant accounts are strictly separated at the application level — a tenant can only ever see their own tenancy, and certain landlord-only records (e.g. vetting/reference checks) are never exposed to a tenant-facing view. Two-factor authentication (authenticator app or email code, plus backup codes) is available and can be enabled independently by any user.
Backups
Our database is backed up automatically before any maintenance operation that could affect stored data, with an additional on-demand backup process available to our team at any time.
Reporting a security issue
If you believe you've found a security vulnerability in Tenarize, please email info@tenarize.com with details — we'll acknowledge and investigate promptly. Please don't publicly disclose an issue before we've had a chance to address it.